Home / Companies / Socket / Blog / Post Details
Content Deep Dive

North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads

Blog post from Socket

Post Details
Company
Date Published
Author
-
Word Count
2,680
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

Since 2024, over 1,700 malicious packages linked to North Korea's Contagious Interview operation have been tracked, with recent developments revealing a new cluster of threat actors operating under GitHub aliases like golangorg. They have published malware across multiple open-source ecosystems, impersonating legitimate developer tools while functioning as malware loaders. These malicious packages, spread across npm, PyPI, Go Modules, Rust’s crates.io, and PHP's Packagist, include functionalities for remote access, keylogging, and data theft, including browser and cryptocurrency wallet data. The threat actors hide their malicious code behind seemingly legitimate functions within these packages, making them difficult to detect. The operation's infrastructure and package construction are consistent with Contagious Interview's previous tactics, utilizing a coordinated cross-ecosystem supply chain strategy. Efforts to remove these packages from affected registries are ongoing, and the campaign underscores the importance of scrutinizing utility packages that interact with remote infrastructure.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.